diff --git a/detections/web/citrix_adc_exploitation_cve_2023_3519.yml b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml index 61d7835a18..b68e0e1635 100644 --- a/detections/web/citrix_adc_exploitation_cve_2023_3519.yml +++ b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml @@ -29,13 +29,6 @@ references: - https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467 - https://securityintelligence.com/x-force/x-force-uncovers-global-netscaler-gateway-credential-harvesting-campaign/ - https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967 -rba: - message: Possible expliotation of CVE-2023-3519 against $dest$. - risk_objects: - - field: dest - type: system - score: 45 - threat_objects: [] tags: analytic_story: - Citrix Netscaler ADC CVE-2023-3519 diff --git a/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml b/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml index 44af6c8de7..c142ab0a2d 100644 --- a/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml +++ b/detections/web/citrix_sharefile_exploitation_cve_2023_24489.yml @@ -32,13 +32,6 @@ known_false_positives: False positives may be present, filtering may be needed. Hunting to TTP. references: - https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/ -rba: - message: Possible expliotation of CVE-2023-24489 against $dest$. - risk_objects: - - field: dest - type: system - score: 45 - threat_objects: [] tags: analytic_story: - Citrix ShareFile RCE CVE-2023-24489 diff --git a/detections/web/hunting_for_log4shell.yml b/detections/web/hunting_for_log4shell.yml index 1b2a91b49c..ecfdc97ccc 100644 --- a/detections/web/hunting_for_log4shell.yml +++ b/detections/web/hunting_for_log4shell.yml @@ -43,15 +43,6 @@ references: - https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/ - https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c - https://twitter.com/sasi2103/status/1469764719850442760?s=20 -rba: - message: Hunting for Log4Shell exploitation has occurred. - risk_objects: - - field: dest - type: system - score: 40 - threat_objects: - - field: src - type: ip_address tags: analytic_story: - Log4Shell CVE-2021-44228 diff --git a/detections/web/vmware_server_side_template_injection_hunt.yml b/detections/web/vmware_server_side_template_injection_hunt.yml index fce710c7e9..4bf925dc15 100644 --- a/detections/web/vmware_server_side_template_injection_hunt.yml +++ b/detections/web/vmware_server_side_template_injection_hunt.yml @@ -33,14 +33,6 @@ references: - https://www.vmware.com/security/advisories/VMSA-2022-0011.html - https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis - https://twitter.com/wvuuuuuuuuuuuuu/status/1519476924757778433 -rba: - message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on - $dest$ has occurred. - risk_objects: - - field: dest - type: system - score: 35 - threat_objects: [] tags: analytic_story: - VMware Server Side Injection and Privilege Escalation diff --git a/detections/web/windows_iis_server_pswa_console_access.yml b/detections/web/windows_iis_server_pswa_console_access.yml index bba6898580..d964f3f764 100644 --- a/detections/web/windows_iis_server_pswa_console_access.yml +++ b/detections/web/windows_iis_server_pswa_console_access.yml @@ -27,15 +27,6 @@ known_false_positives: False positives may occur if legitimate PSWA processes ar between legitimate and malicious activity. references: - https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a -rba: - message: Access to the PowerShell Web Access (PSWA) console detected from $src$. - risk_objects: - - field: dest - type: system - score: 32 - threat_objects: - - field: src - type: ip_address tags: analytic_story: - CISA AA24-241A